terraform-policy
Write, test, or convert Terraform Policy files (.policy.hcl, .policytest.hcl, Sentinel→tfpolicy). Triggers: policy.hcl, policytest, convert sentinel, tfpolicy, write a policy.
How do I install this agent skill?
npx skills add https://github.com/hashicorp/agent-skills --skill terraform-policyIs this agent skill safe to install?
- Gen Agent Trust Hubpass
This skill provides a comprehensive suite of instructions and references for authoring, testing, and converting Terraform Policies. It emphasizes security best practices, such as null-safety patterns and verification against official provider documentation.
- Socketpass
No alerts
- Snykwarn
Risk: MEDIUM · 1 issue
What does this agent skill do?
terraform-policy
UTILITY SKILL — INVOKES: tfpolicy-author | tfpolicy-test
USE FOR:
- Writing a new
.policy.hclpolicy from a description or requirement - Converting a
.sentinelpolicy to Terraform Policy - Writing or debugging a
.policytest.hcltest file - Migrating a Sentinel policy library to Terraform Policy
Before giving authoring or testing instructions, check the installed tfpolicy CLI version and tailor guidance accordingly:
- If the CLI is
0.1.x, do not requirepolicy { required_providers { ... } }; generate policies compatible with tfpolicy 0.1.x syntax and behavior. - If the CLI is
0.2.0or newer, include a top-levelpolicy { required_providers { ... } }block when authoring.policy.hcl. It is mandatory fortfpolicy validate; version-range validation is best effort, and wildcard targets such asresource_policy "*"are not schema-validated. - If the CLI version is unknown, ask the user to check it first or provide guidance that clearly distinguishes the
0.1.xand0.2.0+paths.
DO NOT USE FOR:
- Writing
.tftest.hclfiles for Terraform modules — useterraform-test - General Terraform HCL authoring — use
terraform-style-guide
Routing
| Task | Sub-skill |
|---|---|
Write or convert a .policy.hcl policy | tfpolicy-author |
Write or debug a .policytest.hcl test | tfpolicy-test |
Examples
- "Block EC2 instances without encryption" → tfpolicy-author
- "Convert this Sentinel policy to tfpolicy" → tfpolicy-author
- "Write a policytest for my EBS policy" → tfpolicy-test
Troubleshooting
- Wrong skill triggered? Load the sub-skill directly from the routing table above.
npx skills add hashicorp/agent-skills/terraform/terraform-policy/skills/tfpolicy-author
npx skills add hashicorp/agent-skills/terraform/terraform-policy/skills/tfpolicy-test
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/hashicorp/agent-skills/terraform-policy">View terraform-policy on skillZs</a>